CVE-2019-25031 PUBLISHED

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that facilitates automatic configuration creation. It is not part of the Unbound installation

EPSS 0.81% · 74.1th percentile

Risk Scores

EPSS Score
0.81%
74.1th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSunbound0, 1.9.0-2ubuntu1, 1.9.0-2ubuntu2
Ubuntu:18.04:LTSunbound1.6.7-1ubuntu2.1, 0, 1.6.7-1ubuntu2.3

Timeline

References

Open in Interactive Console →